On 4 August, two days after the AI Act’s transparency rules went live, a Turkish SaaS founder got an email from her biggest German customer: “Please confirm your chatbot complies with Article 50 and describe your synthetic-content marking.” She had eleven users in the flow, a launch that week, and no answer. This guide is the answer, written for the first weeks of the new regime.
What actually switched on, and what it costs to ignore
Since 2 August 2026, Article 50 of the AI Act applies, and so does the member-state penalty framework. Four duties matter for most products: tell people they are interacting with an AI system unless it is obvious; mark AI-generated audio, image, video and text output in a machine-readable way; disclose deepfakes; and disclose AI-generated text published to inform the public on matters of public interest. Unlike the high-risk regime (postponed to December 2027), none of this was deferred by the omnibus.
The two-week runbook
Days 1–3: inventory. List every surface where your system talks to a human or emits content: chat widgets, voice bots, e-mail drafting, image generation, auto-published summaries. For each, record whether a “reasonable person” would know it is AI. Days 4–7: disclosure layer. Chat and voice interfaces get an explicit notice at first interaction; keep it in the interface, not buried in terms. Days 8–11: marking layer. Generated media needs machine-readable marking (metadata, provenance standards or watermarking where feasible); check what your model vendor already embeds before building your own; most foundation-model APIs now ship provenance metadata you must preserve rather than strip. Days 12–14: evidence. Screenshot the notices, document the marking pipeline, and answer the customer questionnaire once, well, in a reusable memo.
The four traps we keep seeing
First: assuming the exemption for “obvious” AI covers your product; it is judged from the user’s perspective, and enterprise buyers will not take your word for it. Second: stripping vendor-supplied provenance metadata in your pipeline, which converts compliant output into non-compliant output. Third: treating Article 50 as an EU-only issue while serving EU users from Türkiye; the Act applies to output used in the Union. Fourth: forgetting the Turkish layer; the pending TCK amendment bill would require visible “AI-generated” labels on deepfake content with a six-hour takedown rule, so build labelling once, for both regimes.
The four duties at a glance
| Duty | Who carries it | Typical product surface | What “done” looks like |
|---|---|---|---|
| AI-interaction disclosure | Provider | Chatbots, voice bots, AI e-mail agents | Notice at first interaction, visible in-interface, screenshot archived |
| Machine-readable marking of synthetic output | Provider | Image/audio/video/text generation features | Provenance metadata or watermark present in output files; vendor metadata preserved end-to-end |
| Deepfake disclosure | Deployer | Marketing creative, avatars, cloned voices | Visible label on the content itself, not only in a description field |
| Public-interest text disclosure | Deployer | AI-written news, analyses, public reports | Disclosure of AI generation unless human editorial review took responsibility |
A worked example: one SaaS, three surfaces
Take a CRM product with an AI e-mail assistant, an in-app support chatbot and an auto-generated “market news” digest. The chatbot needs the interaction notice (surface one). The e-mail assistant’s drafts are synthetic text sent under a user’s name; mark them internally and let the human sender take responsibility on send, documenting that review step (surface two). The digest is AI-generated text informing the public: it needs its own disclosure line unless an editor signs off each issue (surface three). Three different rules, one afternoon of product work, but only if someone maps the surfaces first, which is precisely what enterprise buyers now ask to see.
Does Article 50 apply to plain B2B tools?
Yes, where humans interact with the system or content reaches the public; internal-only tooling with professional users still deserves the disclosure as vendor hygiene, and your enterprise customers will contractually require it anyway.
Are there penalties already?
The penalty framework applies from 2 August 2026; national authorities enforce it. Early enforcement typically starts with the loudest consumer-facing failures; undisclosed chatbots and unlabelled synthetic media.
This week’s homework
Run the day 1–3 inventory. If any surface fails the “would my user know?” test, ship the notice this sprint; it is a UI string, not a project. Then ask your model vendor one question in writing: “What provenance metadata do you embed, and do your terms let me remove it?”
For the timeline and the rest of the stack, see the AI Compliance Hub.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro call